Bugcrowd - is crowd-sourced security testing a good idea? "We use the power of the crowd to find and eliminate security vulnerabilities" Bugcrowd offers managed "bug bounty" programs for businesses... but is crowd-sourced security testing actually a good idea? First, let's take a look at the registration screen. "A steady stream of new targets to hone your skills" Put another way... " don't focus on one target, try as many as possible while you learn the trade" Security testing is a serious business. It requires absolute focus by a team of
Information Commissioners Office - Security Review "The Information Commissioner’s office (ICO) is the UK’s independent public authority set up to uphold information rights. We do this by promoting good practice, ruling on complaints, providing information to individuals and organisations and taking appropriate action when the law is broken." "We are responsible for data protection in England, Scotland, Wales and Northern Ireland; we also have some international duties." With responsibilities like that, you'd expect the ICO to be the pinnac
companies house Companies House Security Review - Part 2 Update(s): 18/Dec/2012 - One SSL bug now fixed (might want to put security testing out to tender next time!) - but still a few to go. Directory traversal still possible... hint encode/escape or strip, don't add slashes! Significant improvements have been made to the SSL implementation - now scoring a healthy Grade A @ Qualys SSL Labs. At least progress is being made... can't fault them for that. 17/Dec/2012 - WebCheck now uses cookies - but still not secure! At this point, I'm not sure wh
companies house Corporate Identity Theft - Perhaps the biggest risk is where you least expect it... Update(s): 18/Dec/2012 - One SSL bug now fixed (might want to put security testing out to tender next time!) - but still a few to go. Directory traversal still possible... hint encode/escape or strip, don't add slashes! Significant improvements have been made to the SSL implementation - now scoring a healthy Grade A @ Qualys SSL Labs. At least progress is being made... can't fault them for that. 17/Dec/2012 - WebCheck now uses cookies - but still not secure! At this point, I'm not sure w
Santander: Input validation & output encoding, what's that? In order to handle data safely, a developer must understand exactly what data they're dealing with and the context within which it's used. Web/App developers (good ones at least) treat all data, regardless of its source, as potentially dangerous. As such, they have to validate (and where necessary, encode) everything you type in to their apps. If we ask for a phone number, we expect you to enter a number. If we ask for an email address, we expect the format to conform to that of an email a
santander Santander aren't secure - Should we bank online? "Your financial protection is our priority and we take this very seriously" "Our service actively protects both your identity and your finances." "We take every step possible to keep your finances and personal details safe." Confident statements; so you'd be forgiven for having equal confidence in their abilities to protect your information. In November 2011, I contacted Santander to alert them to several security concerns which needed to be addressed. Take the "online security" page for e